Zscaler Reports 935% Surge in Ransomware Attacks on Oil and Gas Sector
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
According to Zscaler’s recent report, ransomware attacks on the oil and gas sector surged by 935% between April 2024 and April 2025. This significant rise has raised alarms among cybersecurity experts, as the oil and gas industry was previously considered relatively secure from such threats. The report indicates that nearly 50% of these attacks were concentrated in the United States, making it the most affected country among 15 nations analyzed.
The report also highlights a troubling trend in ransomware tactics, moving from simple data encryption to more sophisticated double extortion methods. In this approach, attackers not only encrypt the victim’s data but also exfiltrate sensitive information, threatening to release or sell it if the ransom is not paid. This shift indicates a more aggressive monetization strategy by cybercriminals, increasing the stakes for organizations.
Zscaler identified three major ransomware groups responsible for this surge: RansomHUB, which had 833 reported victims; Akira, with 520 victims; and Clop, which accounted for 488 victims. These groups are employing various strategies to maximize their payouts, contributing to the overall increase in ransomware incidents.
Despite the alarming growth in ransomware attacks, there is a silver lining. Zscaler notes that while the number of ransomware gangs is increasing, many new groups are struggling to maintain operations due to intensified law enforcement efforts. Initiatives like Operation Cronos and Operation Checkmate have disrupted several prominent cybercrime syndicates, impacting the sustainability of these gangs.
In total, 34 new ransomware gangs emerged between April 2024 and April 2025, bringing the total to 425 active groups. This rapid growth underscores the appeal of ransomware as a profitable criminal enterprise. However, ongoing global law enforcement crackdowns may help curb this trend, as authorities continue to dismantle cybercrime networks.
The rise in ransomware attacks on the oil and gas sector serves as a wake-up call for organizations across various industries. With evolving attack methods and the increasing number of ransomware groups, businesses must enhance their cybersecurity measures to protect against these threats.
Implications for Cybersecurity
The significant increase in ransomware attacks highlights the need for organizations to reassess their cybersecurity strategies. The shift to double extortion tactics means that businesses must not only focus on preventing data breaches but also on protecting sensitive information from being exfiltrated. This requires a comprehensive approach to cybersecurity, including regular audits, employee training, and robust data protection measures.
Organizations should also monitor for signs of ransomware activity and ensure they have incident response plans in place. As the landscape of cyber threats continues to evolve, staying informed about the latest tactics used by cybercriminals will be crucial in mitigating risks.
Key Takeaways
- Review and strengthen your cybersecurity protocols to guard against ransomware attacks.
- Implement data encryption and access controls to protect sensitive information from exfiltration.
- Conduct regular employee training on recognizing phishing attempts and other cyber threats.
- Establish an incident response plan to quickly address potential ransomware incidents.
- Stay updated on the latest ransomware tactics and trends to enhance your organization’s defenses.
Key Terms & Concepts
- Ransomware: In this article, ransomware refers to malicious software that encrypts a victim’s data, demanding payment for its release.
- Double extortion: Double extortion is a tactic where attackers encrypt data and also steal sensitive information, threatening to release it if the ransom is not paid.
- RansomHUB: RansomHUB is identified as the most prolific ransomware group, responsible for 833 reported victims between 2024 and 2025.
- Operation Cronos: Operation Cronos is a law enforcement initiative aimed at disrupting cybercrime syndicates involved in ransomware attacks.
- Ransomware-as-a-service (RaaS): Ransomware-as-a-service refers to a business model where ransomware tools are provided to criminals for a fee, facilitating their attacks.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.